---
id: CVE-2026-81578
title: >-
  An improper access control vulnerability exists in the web management
  interface of PaperCut MF and PaperCut NG
summary: "An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific\_conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions pri…"
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-305
vendor: papercut
product: papercut_mf
affected:
  - papercut_mf < 24.1.9
  - 'papercut_mf >= 25.0.2, < 25.0.12'
  - 'papercut_mf >= 26.0.2, < 26.0.4'
  - papercut_ng < 24.1.9
  - 'papercut_ng >= 25.0.2, < 25.0.12'
  - 'papercut_ng >= 26.0.2, < 26.0.4'
patched:
  - papercut_mf 26.0.4
  - papercut_ng 26.0.4
published: '2026-08-28'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T00:16:56.207'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81578'
references:
  - url: >-
      https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/
    label: eb41dac7-0af8-4f84-9f6d-0272772514f4
  - url: 'https://github.com/rapid7/metasploit-framework/pull/21842'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-81578
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - in-the-wild
  - exploit-available
  - kev
exploited: true
exploitAvailable: true
ssvc:
  exploitation: active
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-08-28T00:00:00+00:00'
scores:
  nvd: 9.8
  cna: 8.8
ingestedAt: '2026-09-14T15:24:01.305Z'
epss: 0.04481
epssPercentile: 0.91124
kev: true
kevDateAdded: '2026-08-31'
kevDueDate: '2026-09-14'
kevRansomware: false
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/yora1928/PaperCut-CVE-2026-81578-82078'
    - 'https://github.com/virologi-info/papercut-toolkit'
  metasploit:
    - exploit/multi/http/papercut_ng_external_user_lookup_rce
  nuclei:
    - CVE-2026-81578
  checkedAt: '2026-09-27T10:34:01.855Z'
---

## Overview

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the  completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

## Affected

- `papercut_mf < 24.1.9`
- `papercut_mf >= 25.0.2, < 25.0.12`
- `papercut_mf >= 26.0.2, < 26.0.4`
- `papercut_ng < 24.1.9`
- `papercut_ng >= 25.0.2, < 25.0.12`
- `papercut_ng >= 26.0.2, < 26.0.4`

## Remediation

Upgrade past the affected range:

- `papercut_mf 26.0.4`
- `papercut_ng 26.0.4`
